Legal centre

Privacy Policy

This policy explains what personal data we handle when you visit manzilone.com or use the Manzil One platform, why we handle it, and the choices you have. We have written it to be read, not to be survived.

Last updated 26 July 2026

1. Who we are

Manzil One is an AI enterprise transformation platform operated by [Registered legal entity name] (Digiware), registered at [Registered office address], registration [Company registration number].

Where you use Manzil One as a customer, you are the controller of the personal data you put into your workspace and we act as your processor for that data. We are the controller for the limited data we hold about our own relationship with you — account records, billing contacts, support correspondence and website analytics.

For any privacy question, or to exercise a right described below, write to privacy@manzilone.com.

2. What we collect

We group the data into four categories.

Account data
Your name, work email address, organisation, role and permission assignments, hashed password, profile photograph if you upload one, interface language and theme preference. This is what lets you sign in and lets your administrator decide what you may see.
Workspace content
The business records you and your colleagues create — leads, opportunities, customers, contacts, RFQs, quotations, rate cards, projects, tasks, RAID items, activities, comments and attachments. This content may contain personal data about your own customers and staff. It belongs to your organisation; we process it on your instructions.
Technical and usage data
IP address, browser and device type, pages and features used, timestamps, and error diagnostics. We use this to keep the service secure and working, and to understand which features earn their keep.
Correspondence
Messages you send us — demo requests, support enquiries, security reports — and our replies.

We do not ask for, and ask that you do not put into the platform, special-category personal data (health, biometric, religious or political data), payment card numbers, or government identity numbers. Manzil One is not designed to hold them.

3. Why we process it, and on what basis

PurposeData usedBasis
Providing the platform to your organisationAccount data, workspace contentPerformance of our contract with your organisation
Authenticating you and maintaining your sessionAccount data, technical dataPerformance of contract
Keeping the service secure, preventing abuse, investigating incidentsTechnical data, audit recordsLegitimate interests in operating a secure service
Diagnosing faults and improving reliability and featuresTechnical and usage dataLegitimate interests
Producing AI-assisted drafts and summaries when your administrator enables themThe specific records referenced by the requestPerformance of contract, on your instruction
Responding to your enquiriesCorrespondenceLegitimate interests, or performance of contract
Meeting legal, tax and accounting obligationsAccount data, billing recordsLegal obligation

We do not sell personal data, we do not share it with advertising networks, and we do not use it to build profiles for marketing.

4. AI features

AI assistance is optional and controlled by your administrator. When it is switched on, and only when a user actively asks for something, the specific records needed to answer that request are sent to the configured model provider so that the requested draft, summary or explanation can be produced.

  • Your workspace content is never used to train any model, ours or a provider's.
  • Requests are made only in response to a user action — nothing is sent in the background.
  • The provider credential is held in your own configuration and can be rotated or removed at any time.
  • Switching AI off leaves the rest of the platform fully functional.
  • AI output is a draft. Commercial figures are always computed by the platform from your rate cards, not generated by the model.

5. Who else processes it

We use a small number of infrastructure providers as sub-processors. Each is bound by contract to process data only on our instructions and to protect it appropriately. The current list, with what each one does and where it operates, is published at /sub-processors and forms part of this policy.

Beyond those, we disclose personal data only: to your own organisation's administrators, as your workspace configuration allows; to professional advisers under confidentiality; where required by law or to establish or defend legal claims; and to a successor entity in a merger or acquisition, on the same terms as this policy.

6. International transfers

Workspace data is stored in managed Postgres in the Asia-Pacific (Tokyo) region, with serverless compute pinned to the same region so requests and data stay together. Some sub-processors operate global control planes, which can mean support and administrative access from other countries.

Where personal data moves outside its country of origin, we rely on the transfer mechanism appropriate to that route — typically the relevant standard contractual clauses together with technical measures including encryption in transit. Details of the mechanism for a specific provider are available on request during procurement.

7. How long we keep it

  • Workspace content: for as long as your organisation's subscription is active. On termination it is deleted or returned in line with the Terms of Service, after a short grace period intended to protect you against accidental cancellation.
  • Account data: for the life of the account, then deleted or anonymised.
  • Audit records: retained for the life of the account because their entire purpose is to be a durable record of who did what.
  • Technical logs: a short rolling window, typically measured in weeks, then discarded.
  • Correspondence: as long as needed to handle the matter and for a reasonable period afterwards.
  • Records we must keep for tax or accounting reasons: for the statutory period.

8. How we protect it

Every workspace is addressed by its own hostname and resolved on the server before any query runs; the environment forms part of that identity, so a development workspace and a production workspace are genuinely separate organisations. Queries are organisation-scoped, an unknown or inactive tenant fails closed rather than falling back to a default, access is governed by a role-and-permission matrix enforced on the server for every route, credentials are stored hashed, and sessions are held server-side. The full description is at /security.

No system is perfectly secure. If you believe you have found a vulnerability, please tell us at security@manzilone.com and give us a reasonable opportunity to fix it before disclosing it publicly.

9. Your rights

Depending on where you are, you may have the right to access the personal data we hold about you, to have it corrected, to have it erased, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent where consent is the basis we rely on.

If your data is in a customer's workspace, that customer is the controller — please raise the request with them and we will support them in answering it. For data we control, write to privacy@manzilone.com. We will respond within the period the applicable law allows, and we will not charge you for a reasonable request.

You also have the right to complain to your local data-protection authority. We would rather you came to us first, but that right is yours either way.

10. Children

Manzil One is a business tool sold to organisations. It is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe we have, tell us and we will delete it.

11. Changes to this policy

We will update this policy when the way we handle data changes. The revision date at the top always reflects the current version, and we will give customers reasonable advance notice of any change that materially reduces the protection this policy provides.